Certified Cloud Security Professional (CCSP) — Questions and Answers
Question 1: Which phase of the incident response lifecycle focuses on restoring systems to normal operations after a security incident?
- Recovery (Correct answer)
- Post-Incident Activity
- Preparation
- Detection and Analysis
Correct answer: Recovery
The Recovery phase involves restoring and validating systems to return to normal business operations after containment and eradication of the threat.
Question 2: In the context of cloud data security, what is a data custodian responsible for?
- Implementing and managing the technical security controls that protect data (Correct answer)
- Purchasing cloud storage services
- Defining data classification policies
- Approving data access requests from executives
Correct answer: Implementing and managing the technical security controls that protect data
The data custodian is responsible for the day-to-day management and technical protection of data as specified by the data owner.
Question 3: What is data sovereignty in the context of cloud storage?
- Encrypting data before uploading to a cloud provider
- Automatic replication of data across multiple regions
- The principle that data is subject to the laws of the country in which it is stored (Correct answer)
- The cloud provider's right to audit stored data
Correct answer: The principle that data is subject to the laws of the country in which it is stored
Data sovereignty means that stored data is governed by the legal jurisdiction of the country where the physical storage resides.
Question 4: Which cloud deployment model is operated solely for a group of organizations with shared missions, security requirements, or compliance objectives?
- Private cloud
- Public cloud
- Community cloud (Correct answer)
- Hybrid cloud
Correct answer: Community cloud
A community cloud is provisioned for a specific community of consumers with common concerns such as shared mission, security requirements, policy, or compliance considerations.
Question 5: Which cloud storage type is best suited for unstructured data such as images, videos, and backups?
- In-memory storage
- Object storage (Correct answer)
- Block storage
- File storage
Correct answer: Object storage
Object storage is designed for unstructured data, storing items as objects with metadata and a unique identifier rather than in a hierarchical file system.
Question 6: What is the primary security concern with container escapes in a cloud environment?
- Containers cannot be encrypted
- Container images are too large
- An attacker who escapes a container can potentially access the host OS and other containers (Correct answer)
- Containers use too much CPU
Correct answer: An attacker who escapes a container can potentially access the host OS and other containers
A container escape vulnerability allows a process inside a container to break out to the host kernel, potentially compromising the entire host and co-located containers.
Question 7: In the context of cloud eDiscovery, what is the primary challenge compared to on-premises environments?
- Cloud systems cannot produce logs
- eDiscovery tools do not work on cloud data
- Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection (Correct answer)
- Cloud providers have too much storage
Correct answer: Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection
Cloud eDiscovery challenges include multi-jurisdictional data storage, commingling of data across tenants, and limited customer access to enforce legal holds on provider-managed infrastructure.
Question 8: What is the primary security concern introduced by multitenancy in cloud computing environments?
- Difficulty in deploying applications across multiple instances
- Inability to enforce encryption for individual tenants
- Potential for data leakage or unauthorized access between co-located tenant workloads (Correct answer)
- Increased latency due to shared network bandwidth
Correct answer: Potential for data leakage or unauthorized access between co-located tenant workloads
Multitenancy introduces the risk that tenant data or workloads could be exposed to other tenants through misconfigurations, virtualization vulnerabilities, or side-channel attacks on shared infrastructure.
Question 9: What is the primary purpose of identity federation in cloud computing environments?
- To enable users to authenticate once and access resources across multiple cloud services using a single identity (Correct answer)
- To encrypt user credentials stored across cloud identity providers
- To duplicate user accounts across multiple cloud platforms for redundancy
- To restrict each user to accessing only a single cloud provider
Correct answer: To enable users to authenticate once and access resources across multiple cloud services using a single identity
Identity federation enables single sign-on (SSO) across multiple cloud services by establishing trust between identity providers, reducing authentication complexity and credential sprawl.
Question 10: How frequently should efforts to control cables be made?
- Annually
- Weekly
- Quarterly
- Continually (Correct answer)
Correct answer: Continually
Cable management efforts should take place continually. It is important to maintain organized and tidy cables throughout the lifespan of the network infrastructure. Regularly inspecting and managing cables helps prevent potential issues such as cable damage, interference, or accidental disconnections. Continual cable management ensures a clean and efficient network environment.
Question 11: Which concept in cloud contracts ensures the customer retains ownership of their data and can retrieve it upon contract termination?
- Data portability and right to return clause (Correct answer)
- Force majeure clause
- Indemnification clause
- Non-disclosure agreement
Correct answer: Data portability and right to return clause
A data portability and right to return clause contractually guarantees that the customer can export their data in a usable format and that the provider will delete it after contract termination.
Question 12: In the context of DevSecOps, what does 'shift left' security mean?
- Using left-handed encryption algorithms
- Integrating security practices early in the development lifecycle rather than only at the end (Correct answer)
- Shifting security team responsibilities to developers entirely
- Moving security testing to the left side of the screen in dashboards
Correct answer: Integrating security practices early in the development lifecycle rather than only at the end
Shifting left means introducing security testing, code analysis, and threat modeling early in development rather than waiting until the deployment or production phase.
Question 13: What is the primary purpose of a Business Associate Agreement (BAA) in the context of HIPAA compliance in the cloud?
- To authorize the cloud provider to share medical data with third parties
- To certify that a cloud provider has passed a HIPAA audit
- To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements (Correct answer)
- To establish pricing between a company and its cloud provider
Correct answer: To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements
A BAA is a legally binding contract required by HIPAA whenever a covered entity shares protected health information (PHI) with a third-party service provider.
Question 14: What is the sole data format supported by the SOAP API?
- HTML
- XML (Correct answer)
- SAML
- XSML
Correct answer: XML
Only the XML data format is supported by the SOAP protocol.
Question 15: What is the main purpose of a Cloud Access Security Broker (CASB)?
- To replace the cloud provider's built-in firewall
- To encrypt data before it reaches the cloud provider
- To provide multi-factor authentication to cloud portals
- To act as an intermediary that enforces security policies between cloud users and cloud services (Correct answer)
Correct answer: To act as an intermediary that enforces security policies between cloud users and cloud services
A CASB sits between cloud service consumers and providers to enforce visibility, compliance, data security, and threat protection policies.
Question 16: What is the key architectural difference between containers and virtual machines (VMs)?
- Containers include a full OS per instance; VMs share the host OS kernel
- Containers require Type 1 hypervisors; VMs use Type 2 hypervisors only
- Containers are used only for stateless applications; VMs support only stateful workloads
- Containers share the host OS kernel; VMs include a complete guest OS per instance (Correct answer)
Correct answer: Containers share the host OS kernel; VMs include a complete guest OS per instance
Containers share the host OS kernel and isolate only the application and its dependencies, making them more lightweight, while VMs include a full guest OS per instance.
Question 17: A cloud customer wants to ensure their data is never stored outside a specific geographic region. Which control best addresses this requirement?
- Intrusion Detection System (IDS)
- Contractual data residency clause with the CSP (Correct answer)
- Multi-factor authentication
- Data Loss Prevention (DLP) policy
Correct answer: Contractual data residency clause with the CSP
A contractual data residency clause legally obligates the cloud service provider to keep customer data within the specified geographic boundary.
Question 18: Which sort of audit report do many cloud providers employ to reassure current and prospective clients about their policies, methods, and procedures?
- SOC 2 (Correct answer)
- SAS-70
- SOX
- SOC 1
Correct answer: SOC 2
Many cloud providers choose to conduct a SOC 2 audit and make the report available to cloud clients and potential cloud customers as a means to convey security confidence without having to expose their systems or sensitive information to the public.
Question 19: After the initial tests, which of the following threat types involves an application that does not validate authorization for portions of itself?
- Injection
- Cross-site request forgery
- Missing function-level access control (Correct answer)
- Cross-site scripting
Correct answer: Missing function-level access control
When each function or component of an application is accessed, an application must run checks to ensure that the user is legitimately permitted to access it. An attacker could fabricate requests to access areas of the application where authorization has not been granted if continuous checks are not performed each time a function is accessed.
Question 20: What is the primary risk of storing sensitive data in JWT (JSON Web Token) payloads?
- JWTs are limited to 256 bytes
- JWTs cannot be transmitted over HTTPS
- JWTs expire too quickly for production use
- JWT payloads are base64-encoded but not encrypted by default, making the data readable if intercepted (Correct answer)
Correct answer: JWT payloads are base64-encoded but not encrypted by default, making the data readable if intercepted
JWT payloads are only base64url-encoded, not encrypted, so anyone who intercepts or decodes the token can read the claims within it.
Question 21: In cloud infrastructure, what is infrastructure as code (IaC) primarily used for?
- Monitoring cloud resource performance
- Billing and cost management
- Writing application source code for cloud-native apps
- Provisioning and managing infrastructure through machine-readable configuration files (Correct answer)
Correct answer: Provisioning and managing infrastructure through machine-readable configuration files
IaC allows infrastructure to be defined, versioned, and deployed using code, enabling consistent, repeatable, and auditable provisioning.
Question 22: What is the role of the Data Protection Officer (DPO) under GDPR?
- To conduct penetration tests on cloud environments
- To sell personal data to marketing partners
- To manage the organization's cloud infrastructure security
- To ensure the organization complies with GDPR, advise on data protection obligations, and act as a contact for supervisory authorities (Correct answer)
Correct answer: To ensure the organization complies with GDPR, advise on data protection obligations, and act as a contact for supervisory authorities
The DPO is an independent role required by GDPR for certain organizations to oversee data protection strategy, ensure compliance, and liaise with data protection authorities.
Question 23: In cloud reference architectures, what does the term 'availability zone' typically refer to?
- A software-defined perimeter protecting cloud workloads from external threats
- An isolated location within a cloud region with independent power, cooling, and networking infrastructure (Correct answer)
- A geographic region where a cloud provider operates multiple data centers
- A virtual network segment that limits access to authorized users only
Correct answer: An isolated location within a cloud region with independent power, cooling, and networking infrastructure
An availability zone is a physically separate, fault-isolated data center within a cloud region with independent infrastructure, enabling high availability through zone-redundant deployments.
Question 24: What is the primary purpose of data classification in a cloud environment?
- To assign appropriate security controls based on sensitivity (Correct answer)
- To enable faster data retrieval
- To reduce storage costs
- To compress data for transmission
Correct answer: To assign appropriate security controls based on sensitivity
Data classification categorizes data by sensitivity so that the appropriate security controls can be applied to each category.
Question 25: What is the primary purpose of conducting a Privacy Impact Assessment (PIA) before deploying a new cloud service?
- To certify the cloud provider as GDPR-compliant
- To estimate the cost of cloud storage for personal data
- To train employees on data handling policies
- To identify and mitigate privacy risks before the service is deployed, ensuring compliance with applicable privacy regulations (Correct answer)
Correct answer: To identify and mitigate privacy risks before the service is deployed, ensuring compliance with applicable privacy regulations
A PIA (or DPIA under GDPR) systematically identifies privacy risks in a new system or process and documents mitigation measures before deployment.
Question 26: What is the key advantage of client-side encryption over server-side encryption in cloud storage?
- Simpler key management
- Lower storage costs
- The cloud provider never has access to the plaintext data or encryption keys (Correct answer)
- Faster upload speeds
Correct answer: The cloud provider never has access to the plaintext data or encryption keys
With client-side encryption, data is encrypted before it leaves the customer's environment, so the cloud provider can only ever see ciphertext.
Question 27: What is Cross-Site Request Forgery (CSRF) and how is it typically mitigated?
- A brute-force attack mitigated by account lockout
- A database attack mitigated by input validation
- An attack that tricks users into submitting unauthorized requests, mitigated by anti-CSRF tokens (Correct answer)
- An XSS variant mitigated by output encoding
Correct answer: An attack that tricks users into submitting unauthorized requests, mitigated by anti-CSRF tokens
CSRF tricks authenticated users into unknowingly submitting requests to a web application; anti-CSRF tokens verify that requests originate from legitimate user sessions.
Question 28: What does the concept of 'data sovereignty' refer to in cloud computing?
- The cloud provider's ownership of customer data stored on their infrastructure
- The customer's right to encrypt all data stored in the cloud
- The legal principle that data is subject to the laws and regulations of the country where it physically resides (Correct answer)
- The ability to retrieve data from cloud storage at any time without restriction
Correct answer: The legal principle that data is subject to the laws and regulations of the country where it physically resides
Data sovereignty means digital data is subject to the laws and governance structures of the nation where it is stored, which is critical when selecting cloud data center locations for regulated data.
Question 29: What is the primary purpose of a Web Application Firewall (WAF) in cloud application security?
- To cache web content for faster delivery
- To filter and monitor HTTP traffic to protect web applications from common exploits (Correct answer)
- To manage API authentication tokens
- To encrypt traffic between the browser and server
Correct answer: To filter and monitor HTTP traffic to protect web applications from common exploits
A WAF inspects HTTP/HTTPS requests and responses, blocking attacks such as SQL injection, XSS, and CSRF before they reach the application.
Question 30: Which CCSP domain specifically addresses the security of data stored, processed, and transmitted in the cloud?
- Cloud Platform and Infrastructure Security
- Cloud Application Security
- Legal, Risk, and Compliance
- Cloud Data Security (Correct answer)
Correct answer: Cloud Data Security
Cloud Data Security is Domain 2 of the CCSP CBK and focuses on data lifecycle management, storage, retention, and protection.
Question 31: In cloud computing, which NIST characteristic allows users to unilaterally provision computing capabilities such as server time and network storage without requiring human interaction with the service provider?
- On-demand self-service (Correct answer)
- Resource pooling
- Measured service
- Rapid elasticity
Correct answer: On-demand self-service
On-demand self-service enables users to provision computing resources automatically as needed without requiring human interaction with each service provider.
Question 32: What is the greatest source of knowledge about safeguarding a physical asset's BIOS?
- Security policies
- Vendor documentation (Correct answer)
- Manual pages
- Regulations
Correct answer: Vendor documentation
The greatest source for recommended practices for safeguarding the BIOS is vendor documentation from the maker of the actual hardware.
Question 33: Which stage of the software development lifecycle (SDLC) is most likely to entail crypto-shredding?
- Define
- Test
- Disposal (Correct answer)
- Design
Correct answer: Disposal
The disposal phase of the software development lifecycle (SDLC) is most likely to involve crypto-shredding. Crypto-shredding, also known as cryptographic erasure or secure data deletion, is a method used to securely delete sensitive information or cryptographic keys from storage media. <br> During the disposal phase, when software or hardware components reach the end of their lifecycle and are being retired or decommissioned, it is crucial to ensure that any sensitive data stored within them is permanently and securely removed. This is particularly important in cases where the data contains personally identifiable information (PII), financial data, trade secrets, or other confidential information.
Question 34: Which technique replaces sensitive data with a non-sensitive substitute that retains the format but has no exploitable value?
- Key stretching
- Tokenization (Correct answer)
- Hashing
- Steganography
Correct answer: Tokenization
Tokenization substitutes sensitive data values with random tokens that are meaningless to an attacker but can be reverse-mapped via a secure vault.
Question 35: Which cloud security architecture model assumes that no user, device, or network segment should be inherently trusted and requires continuous verification for all access requests?
- Role-based access control model
- Zero Trust Architecture (Correct answer)
- Defense-in-depth model
- Perimeter security model
Correct answer: Zero Trust Architecture
Zero Trust Architecture operates on the principle of 'never trust, always verify,' requiring authentication and authorization for every access request regardless of network location or prior session.
Question 36: What is the purpose of threat intelligence sharing in cloud security operations?
- To allow organizations to collectively improve defenses by sharing indicators of compromise and attacker tactics across the community (Correct answer)
- To enable cloud providers to monitor customer data
- To reduce cloud storage costs
- To automate software patching
Correct answer: To allow organizations to collectively improve defenses by sharing indicators of compromise and attacker tactics across the community
Threat intelligence sharing (via ISACs, STIX/TAXII, or commercial feeds) allows organizations to benefit from others' detection and response experiences to defend against known threats faster.
Question 37: Which of the following would be more restrictive when constructing a new data center in an urban setting?
- Utility availability
- Staffing
- Municipal codes (Correct answer)
- The size of the plot
Correct answer: Municipal codes
When building a new data center within an urban environment, municipal codes can indeed be one of the most restrictive aspects. Municipal codes refer to the regulations and requirements imposed by local government authorities to ensure compliance with zoning, building, safety, environmental, and other related standards. <br> Municipal codes typically cover various aspects of construction and operation, including building height and size restrictions, setbacks from property lines, fire safety measures, electrical and mechanical systems, noise control, parking requirements, environmental considerations, and more. These codes are put in place to ensure the safety, sustainability, and compatibility of buildings within the urban landscape.
Question 38: In cloud networking, what does microsegmentation achieve?
- Combines multiple network interfaces into one
- Divides storage into smaller chunks for efficiency
- Compresses network packets for faster transmission
- Isolates individual workloads with granular policy controls, limiting lateral movement by attackers (Correct answer)
Correct answer: Isolates individual workloads with granular policy controls, limiting lateral movement by attackers
Microsegmentation creates fine-grained security zones around individual workloads, so that even if an attacker compromises one, lateral movement is severely restricted.
Question 39: What type of audit report provides a detailed description of a service organization's controls but is intended for restricted distribution?
- SOC 1 Type II
- SOC 2 Type II (Correct answer)
- SOC 3
- ISO/IEC 27001 certificate
Correct answer: SOC 2 Type II
SOC 2 Type II reports provide detailed descriptions and evidence of controls over a period of time and are restricted to customers and stakeholders under NDA.
Question 40: In cloud security, what does UEBA (User and Entity Behavior Analytics) do?
- Enforces access control policies across cloud services
- Establishes behavioral baselines and alerts on anomalous deviations that may indicate insider threats or compromised accounts (Correct answer)
- Automates compliance report generation
- Manages user passwords and MFA enrollment
Correct answer: Establishes behavioral baselines and alerts on anomalous deviations that may indicate insider threats or compromised accounts
UEBA uses machine learning to model normal behavior for users and entities, then flags deviations (e.g., data exfiltration patterns, unusual login times) as potential threats.
Question 41: Which standard specifically provides guidance on personally identifiable information (PII) protection in public clouds?
- PCI DSS
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018 (Correct answer)
Correct answer: ISO/IEC 27018
ISO/IEC 27018 is the code of practice specifically for protection of PII in public cloud computing environments.
Question 42: According to NIST SP 800-145, which of the following is NOT one of the five essential characteristics of cloud computing?
- On-demand self-service
- Dedicated hardware allocation (Correct answer)
- Measured service
- Broad network access
Correct answer: Dedicated hardware allocation
NIST SP 800-145 defines five characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service; dedicated hardware allocation contradicts the shared resource pooling model.
Question 43: Why is input validation considered insufficient as the sole defense against SQL injection?
- Validation can be bypassed through encoding tricks; parameterized queries provide a stronger architectural defense (Correct answer)
- Validation rules cannot be written for SQL
- Input validation makes applications too slow
- Validation only works for web applications, not APIs
Correct answer: Validation can be bypassed through encoding tricks; parameterized queries provide a stronger architectural defense
Input validation alone can be circumvented by encoding or obfuscation; parameterized queries (prepared statements) prevent injection at the architectural level by separating code from data.
Question 44: What is the key difference between vulnerability scanning and penetration testing?
- Vulnerability scanning is illegal; penetration testing is not
- Vulnerability scanning identifies potential weaknesses automatically; penetration testing actively exploits vulnerabilities to determine real impact (Correct answer)
- Penetration testing is automated; vulnerability scanning is manual
- Vulnerability scanning requires physical access; penetration testing is remote only
Correct answer: Vulnerability scanning identifies potential weaknesses automatically; penetration testing actively exploits vulnerabilities to determine real impact
Vulnerability scanners produce lists of potential issues without confirming exploitability, while penetration testers actively attempt to exploit vulnerabilities to assess real-world risk.
Question 45: When evaluating a cloud provider's security posture using the CSA STAR program, which level provides the highest assurance through ongoing automated attestation of security controls?
- Level 4: Government-mandated compliance review and audit
- Level 2: Third-party assessment-based certification (ISO 27001 or SOC 2 + CCM)
- Level 3: Continuous monitoring-based certification with automated attestation (Correct answer)
- Level 1: Self-Assessment using the CAIQ questionnaire
Correct answer: Level 3: Continuous monitoring-based certification with automated attestation
CSA STAR Level 3 represents continuous monitoring-based certification, providing the highest assurance through ongoing automated validation of security controls rather than point-in-time assessments.
Question 46: Which framework provides a set of controls specifically designed to assess the security of cloud service providers?
- CIS Benchmarks
- ISO/IEC 27001
- NIST SP 800-53
- Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) (Correct answer)
Correct answer: Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix (CCM) is a cybersecurity control framework specifically designed for cloud computing, mapping controls to regulatory standards and cloud service models.
Question 47: In secure software development for cloud applications, what does SAST (Static Application Security Testing) analyze?
- Running application behavior in production
- Container image vulnerabilities
- Network traffic between microservices
- Source code or compiled binaries without executing the program (Correct answer)
Correct answer: Source code or compiled binaries without executing the program
SAST tools analyze source code, bytecode, or binaries statically to identify security vulnerabilities early in the development lifecycle before the code runs.
Question 48: What is the primary goal of a Security Information and Event Management (SIEM) system in cloud operations?
- To aggregate, correlate, and analyze security events from multiple sources for threat detection and incident response (Correct answer)
- To encrypt all log data at rest
- To block malicious traffic at the network perimeter
- To manage user identity and access
Correct answer: To aggregate, correlate, and analyze security events from multiple sources for threat detection and incident response
A SIEM centralizes log collection and applies correlation rules to detect suspicious patterns across an organization's entire cloud and on-premises environment.
Question 49: The following capabilities, with the exception of ______, should all be guaranteed by the options included in cloud application designs.
- Data masking
- Encryption of data in transit
- Encryption of data at rest
- Hashing database fields (Correct answer)
Correct answer: Hashing database fields
Software developers designing applications for the cloud should expect to include options to ensure all of the following capabilities except for hashing database fields.
Question 50: What is vendor lock-in risk in cloud computing and how does it affect compliance?
- A compliance requirement to use only approved vendors
- Dependency on a single cloud provider's proprietary technology making migration difficult, which can affect data portability rights under regulations like GDPR (Correct answer)
- The risk of a vendor increasing prices
- The risk of a vendor going bankrupt
Correct answer: Dependency on a single cloud provider's proprietary technology making migration difficult, which can affect data portability rights under regulations like GDPR
Vendor lock-in can conflict with GDPR's right to data portability and make it difficult for organizations to switch providers or comply with data residency requirements.
Question 51: What does the term 'defense in depth' mean when applied to cloud application security?
- Using the deepest available encryption algorithm
- Running security tests after every code commit
- Deeply scanning network packets
- Applying multiple overlapping layers of security controls so that no single failure compromises the whole system (Correct answer)
Correct answer: Applying multiple overlapping layers of security controls so that no single failure compromises the whole system
Defense in depth stacks multiple independent security controls (WAF, authentication, encryption, monitoring) so that an attacker must bypass every layer to succeed.
Question 52: Under the CCSP CBK, what is the difference between legal holds and data retention policies?
- Legal holds require government approval; retention policies do not
- There is no difference; they serve the same purpose
- A legal hold suspends normal deletion schedules for specific data due to litigation, while retention policies define routine minimum and maximum storage durations (Correct answer)
- Retention policies apply to cloud data; legal holds apply only to on-premises data
Correct answer: A legal hold suspends normal deletion schedules for specific data due to litigation, while retention policies define routine minimum and maximum storage durations
Retention policies set standard schedules for keeping or deleting data, while a legal hold overrides those policies for specific data sets that may be needed for litigation or investigation.
Question 53: Which phase of the Cloud Data Lifecycle involves permanently destroying data so it cannot be recovered?
- Use
- Archive
- Destroy (Correct answer)
- Share
Correct answer: Destroy
The Destroy phase of the cloud data lifecycle ensures data is rendered irretrievable using methods like cryptographic erasure or physical destruction.
Question 54: Which data masking technique permanently alters production data for use in non-production environments?
- Dynamic masking
- Pseudonymization
- Tokenization
- Static masking (Correct answer)
Correct answer: Static masking
Static data masking creates a sanitized copy of the data at rest, permanently replacing sensitive values for use in development or testing.
Question 55: When there is a restriction on available resources, which of the following represents a prioritizing of applications or cloud customers for the distribution of extra required resources?
- Limit
- Reservation
- Share (Correct answer)
- Provision
Correct answer: Share
The concept of shares in a cloud environment is used to limit and regulate client requests for resource allocations that the system may not yet be capable of allowing. Work is shared by prioritizing hosts in a cloud environment using a weighting mechanism established by the cloud provider. When periods of high utilization and allocation occur, the system automatically scores each host based on its share value to determine which hosts have access to the few remaining resources. The higher the value of a given host, the more resources it will be permitted to use.
Question 56: What is the shared responsibility model's division regarding physical security of a public cloud data center?
- Entirely the customer's responsibility
- Entirely the cloud service provider's responsibility (Correct answer)
- Shared equally between customer and provider
- Managed by a third-party auditor
Correct answer: Entirely the cloud service provider's responsibility
In all public cloud service models (IaaS, PaaS, SaaS), physical security of the data center infrastructure is always the cloud provider's responsibility.
Question 57: In a Software as a Service (SaaS) deployment, which area does the cloud customer retain primary responsibility for?
- User identity, access management, and data stored in the application (Correct answer)
- Network and server infrastructure
- Application code and features
- Underlying database configuration
Correct answer: User identity, access management, and data stored in the application
In SaaS, the customer's responsibility is primarily limited to managing user access, identity provisioning, and the data they input and store in the application.
Question 58: Which metric measures the average time from when an attack occurs to when it is detected?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Mean Time to Detect (MTTD) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures the average elapsed time between the start of an attack and its detection by the security team.
Question 59: Which term BEST represents the capacity of a cloud environment to automatically scale a system or application based on its current resource demands?
- Rapid elasticity (Correct answer)
- On-demand self- service
- Resource pooling
- Measured service
Correct answer: Rapid elasticity
Rapid elasticity enables a cloud environment to automatically add or withdraw resources from a system or application based on its current needs. Whereas a typical data center approach would need standby hardware and significant effort to add resources in response to load increases, a cloud environment may easily and quickly grow to meet resource demands, as long as the application is appropriately developed.
Question 60: What does the FedRAMP program require cloud service providers to do before selling to US federal agencies?
- Obtain PCI DSS certification
- Complete an ISO 27001 audit
- Achieve a standardized security authorization based on NIST 800-53 controls through third-party assessment (Correct answer)
- Register with the FBI Cyber Division
Correct answer: Achieve a standardized security authorization based on NIST 800-53 controls through third-party assessment
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment and authorization for cloud services sold to US federal agencies.
Question 61: Who should most likely be in charge of maintaining the security of the apps in the production environment in a platform as a service (Paas) model?
- Cloud customer (Correct answer)
- Cloud provider
- Programmers
- Regulator
Correct answer: Cloud customer
In a Platform as a Service (PaaS) model, the cloud customer is typically responsible for the security of the applications in the production environment. While the specific division of responsibilities may vary depending on the service provider and the PaaS offering, the general principle is that the customer retains control and accountability for securing their applications. <br> Under the PaaS model, the cloud provider is responsible for the security of the underlying infrastructure, including the hardware, network, and operating system. They ensure the availability and reliability of the platform, handle patching and updates, and implement measures to protect against common infrastructure-level security threats.
Question 62: What does the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) provide to cloud customers?
- A directory of government-approved cloud vendors
- Real-time security monitoring for cloud environments
- A framework of security controls aligned to cloud-specific risk factors and compliance requirements (Correct answer)
- Pricing benchmarks for cloud security services
Correct answer: A framework of security controls aligned to cloud-specific risk factors and compliance requirements
The CSA CCM provides a framework of control objectives structured across 17 domains to help organizations assess the security risk of cloud providers and map controls to industry standards.
Question 63: What is the key security benefit of using a zero-trust network architecture in the cloud?
- It reduces the cost of cloud networking
- It allows unrestricted access within the internal network
- It eliminates the need for encryption
- It assumes no implicit trust for any user or device, requiring continuous verification regardless of network location (Correct answer)
Correct answer: It assumes no implicit trust for any user or device, requiring continuous verification regardless of network location
Zero trust eliminates the concept of a trusted internal network, requiring identity verification and least-privilege access for every request, reducing breach impact.
Question 64: What is the purpose of a bastion host (jump server) in cloud infrastructure security?
- To load balance traffic across multiple servers
- To provide a hardened, monitored single entry point for administrative access to private network resources (Correct answer)
- To encrypt all traffic within the VPC
- To store encryption keys for cloud resources
Correct answer: To provide a hardened, monitored single entry point for administrative access to private network resources
A bastion host is a specially secured server that serves as the sole access point for SSH/RDP into private cloud networks, reducing the attack surface.
Question 65: In the shared responsibility model for IaaS, which security component is the cloud service provider primarily responsible for securing?
- Customer data
- Hypervisor and physical infrastructure (Correct answer)
- Guest operating systems
- Application configuration
Correct answer: Hypervisor and physical infrastructure
In IaaS, the cloud provider manages the physical hardware and hypervisor layer, while customers are responsible for the OS, applications, and data above that layer.
Question 66: Which cloud architecture principle recommends designing systems to expect and handle component failures gracefully rather than trying to prevent all failures?
- Separation of duties
- Least privilege
- Defense in depth
- Design for failure (Correct answer)
Correct answer: Design for failure
'Design for failure' is a core cloud architecture principle that assumes components will fail and builds systems with automated detection, isolation, and recovery mechanisms to maintain availability.
Question 67: In cloud risk management, what does quantitative risk analysis produce that qualitative analysis does not?
- A color-coded risk heat map
- A list of applicable compliance frameworks
- A descriptive ranking of risks as high, medium, or low
- Numerical estimates of risk in monetary terms (e.g., Annual Loss Expectancy) (Correct answer)
Correct answer: Numerical estimates of risk in monetary terms (e.g., Annual Loss Expectancy)
Quantitative risk analysis calculates numerical values such as ALE (Annual Loss Expectancy) = ARO Ă— SLE, enabling cost-benefit comparison of security controls.
Question 68: Which cloud service model places the MOST infrastructure security responsibility on the cloud customer?
- Function as a Service (FaaS)
- Software as a Service (SaaS)
- Infrastructure as a Service (IaaS) (Correct answer)
- Platform as a Service (PaaS)
Correct answer: Infrastructure as a Service (IaaS)
In IaaS, the customer manages the OS, middleware, runtime, and applications, making them responsible for the largest share of security controls.
Question 69: Which of the following positions is in charge of developing cloud components as well as testing and validating services?
- Inter-cloud provider
- Cloud service developer (Correct answer)
- Cloud auditor
- Cloud service broker
Correct answer: Cloud service developer
The cloud service developer is in charge of designing and building cloud components and services, as well as testing and verifying them.
Question 70: Which secure development practice involves reviewing code written by another developer to identify security flaws before deployment?
- Fuzz testing
- Regression testing
- Threat modeling
- Peer code review / security code review (Correct answer)
Correct answer: Peer code review / security code review
Security-focused code review uses a second developer (or automated tool) to scrutinize code for vulnerabilities before it is merged or deployed.
Question 71: Which regulation requires organizations that handle payment card data to comply with a set of security standards?
- HIPAA
- SOX
- FERPA
- PCI DSS (Correct answer)
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for all organizations that store, process, or transmit cardholder data.
Question 72: What does the term 'cloud bursting' describe in a hybrid cloud architecture?
- The automatic overflow of workloads from a private cloud to a public cloud during demand spikes (Correct answer)
- A failure condition where cloud resource quotas become exhausted
- The process of permanently migrating all workloads to a public cloud
- A DDoS attack targeting cloud infrastructure resources
Correct answer: The automatic overflow of workloads from a private cloud to a public cloud during demand spikes
Cloud bursting allows applications to run in a private cloud and automatically extend to public cloud resources when demand exceeds private cloud capacity, enabling cost-effective scalability.
Question 73: What does the term 'VM sprawl' refer to in cloud environments?
- The uncontrolled proliferation of virtual machine instances that increases attack surface and management overhead (Correct answer)
- VMs with outdated operating systems
- VMs replicating across too many regions
- Virtual machines consuming excessive CPU
Correct answer: The uncontrolled proliferation of virtual machine instances that increases attack surface and management overhead
VM sprawl occurs when virtual machines are created without proper lifecycle management, leading to forgotten, unpatched VMs that expand the attack surface.
Question 74: In a cloud environment, what does automated remediation (auto-remediation) typically do when a misconfiguration is detected?
- Automatically applies corrective actions (e.g., closing an open port, enabling encryption) without human intervention (Correct answer)
- Generates a compliance report for auditors
- Shuts down all cloud resources as a precaution
- Emails the security team to manually fix the issue
Correct answer: Automatically applies corrective actions (e.g., closing an open port, enabling encryption) without human intervention
Auto-remediation uses infrastructure automation to instantly correct detected misconfigurations, reducing the window of exposure without waiting for manual intervention.
Question 75: What is the significance of the EU-US Data Privacy Framework (successor to Privacy Shield) for cloud computing?
- It applies only to government data transfers
- It requires all EU data to be stored in the US
- It bans US cloud providers from offering services in Europe
- It provides a legal mechanism for transferring personal data from the EU to certified US organizations in compliance with GDPR (Correct answer)
Correct answer: It provides a legal mechanism for transferring personal data from the EU to certified US organizations in compliance with GDPR
The EU-US Data Privacy Framework allows US organizations that self-certify to receive EU personal data transfers lawfully under GDPR's requirements for third-country transfers.
Question 76: What is the purpose of a runbook in cloud security operations?
- A physical binder containing server hardware specs
- A compliance checklist for cloud audits
- A documented, step-by-step procedure for responding to specific security incidents or operational tasks (Correct answer)
- A log of all software deployments
Correct answer: A documented, step-by-step procedure for responding to specific security incidents or operational tasks
Runbooks provide standardized, repeatable procedures that operations teams follow during incidents, reducing response time and human error.
Question 77: What does a Data Loss Prevention (DLP) solution primarily do in a cloud environment?
- Monitors and controls the movement of sensitive data to prevent unauthorized exfiltration (Correct answer)
- Encrypts all data before it is stored
- Backs up data to a secondary cloud region
- Detects malware in uploaded files
Correct answer: Monitors and controls the movement of sensitive data to prevent unauthorized exfiltration
DLP solutions inspect and control data flows to detect and prevent the unauthorized transmission of sensitive information outside authorized boundaries.
Question 78: A Type 1 hypervisor differs from a Type 2 hypervisor in which fundamental way?
- Type 1 runs on top of a host OS; Type 2 runs directly on hardware
- Type 1 supports only Linux VMs; Type 2 supports all operating systems
- Type 1 runs directly on host hardware; Type 2 runs on top of a host OS (Correct answer)
- Type 1 is used only in private clouds; Type 2 is used only in public clouds
Correct answer: Type 1 runs directly on host hardware; Type 2 runs on top of a host OS
Type 1 (bare-metal) hypervisors run directly on hardware without an underlying OS for better performance and security, while Type 2 (hosted) hypervisors run as applications on top of a host OS.
Question 79: What is the purpose of chaos engineering in cloud security operations?
- To test employee reactions to ransomware
- To randomly delete cloud resources for cost savings
- To intentionally introduce failures to test system resilience and identify weaknesses before real incidents occur (Correct answer)
- To create disorganized development processes
Correct answer: To intentionally introduce failures to test system resilience and identify weaknesses before real incidents occur
Chaos engineering deliberately injects failures (e.g., terminating instances, dropping network packets) to validate that security and resilience controls work as expected under real failure conditions.
Question 80: Which technique helps detect unauthorized changes to cloud infrastructure configurations?
- Multi-factor authentication
- Continuous configuration monitoring and drift detection (Correct answer)
- Employee awareness training
- Penetration testing
Correct answer: Continuous configuration monitoring and drift detection
Continuous configuration monitoring compares the running infrastructure state against a known-good baseline to detect and alert on unauthorized changes (drift).
Question 81: Which data types are most typically utilized with the REST API?
- XML and JSON (Correct answer)
- JSON and SAML
- SAML and HTML
- XML and SAML
Correct answer: XML and JSON
The most often used data formats for the Representenational State Transfer (REST) API are JavaScript Object Notation (JSON) and Extensible Markup Language (XML), which are typically implemented with caching for enhanced scalability and performance.
Question 82: What does cloud log management best practice require regarding log integrity?
- Logs should be compressed to reduce size and stored locally on each VM
- Logs should be deleted after 30 days to save storage
- Logs should be written to a separate, immutable, write-once storage location to prevent tampering (Correct answer)
- Logs should be stored in the same account as the resources they monitor
Correct answer: Logs should be written to a separate, immutable, write-once storage location to prevent tampering
Logs must be stored in a separate, write-once (immutable) location outside the monitored environment to prevent attackers from covering their tracks by modifying or deleting logs.
Question 83: What is a security group in AWS cloud infrastructure?
- A compliance framework grouping
- A collection of encryption keys managed together
- A virtual stateful firewall that controls inbound and outbound traffic for cloud instances (Correct answer)
- A group of IAM users with shared permissions
Correct answer: A virtual stateful firewall that controls inbound and outbound traffic for cloud instances
AWS Security Groups act as virtual stateful firewalls at the instance level, allowing administrators to define traffic rules based on port, protocol, and source/destination.
Question 84: Which cloud infrastructure component acts as a logical boundary to isolate resources between different tenants or business units?
- Virtual Private Cloud (VPC) (Correct answer)
- Load Balancer
- Content Delivery Network (CDN)
- API Gateway
Correct answer: Virtual Private Cloud (VPC)
A Virtual Private Cloud (VPC) creates an isolated network segment within the cloud provider's infrastructure to separate tenant resources.
Question 85: What is the OWASP Secure Coding Practices guideline's primary recommendation for handling user input?
- Reject all input longer than 50 characters
- Trust all input from authenticated users
- Log all input but do not validate it
- Validate and sanitize all input from untrusted sources (Correct answer)
Correct answer: Validate and sanitize all input from untrusted sources
OWASP recommends treating all input from external sources as untrusted and applying validation, sanitization, and encoding to prevent injection and other attacks.
Question 86: What does the principle of immutable infrastructure mean in cloud security?
- Cloud resources that cannot be deleted
- Servers are never modified after deployment; changes are made by replacing instances with new ones (Correct answer)
- Infrastructure that is always available with 100% uptime
- Infrastructure that cannot be encrypted
Correct answer: Servers are never modified after deployment; changes are made by replacing instances with new ones
Immutable infrastructure replaces running instances rather than patching them in place, reducing configuration drift and ensuring a known-good state.
Question 87: Automation of configuration helps in ____ from the perspective of security.
- Reducing potential attack vectors (Correct answer)
- Increasing ease of use of the systems
- Reducing need for administrative personnel
- Enhancing performance
Correct answer: Reducing potential attack vectors
From a security perspective, automation of configuration aids in reducing potential attack vectors.
Question 88: What is the primary risk of using the same encryption key for a long period without rotation?
- The key becomes too large to store
- Storage costs increase
- Increased probability of key compromise and greater exposure of encrypted data (Correct answer)
- The algorithm weakens over time
Correct answer: Increased probability of key compromise and greater exposure of encrypted data
Prolonged use of a single key increases both the window of exposure and the volume of data at risk if the key is ever compromised.
Question 89: Which attack targets the management plane of a cloud environment to gain control over provisioning and configuration?
- DNS poisoning
- Cloud management plane attack / API abuse (Correct answer)
- Cross-site scripting (XSS)
- SQL injection
Correct answer: Cloud management plane attack / API abuse
The cloud management plane (control plane) is a high-value attack target because compromise of the API or console gives an attacker control over all cloud resources.
Question 90: What is the purpose of a cloud service level agreement (SLA) from a risk and compliance perspective?
- To set employee performance targets
- To specify the price per GB of cloud storage
- To define the cloud provider's marketing commitments
- To contractually define performance, availability, and security obligations, establishing accountability and remedies for non-compliance (Correct answer)
Correct answer: To contractually define performance, availability, and security obligations, establishing accountability and remedies for non-compliance
An SLA establishes measurable service commitments and financial penalties, giving customers contractual recourse if the provider fails to meet security, availability, or compliance obligations.
Question 91: What is the key purpose of a Service Level Agreement (SLA) between a cloud customer and cloud service provider?
- To establish measurable performance commitments, uptime guarantees, and remedies for service failures (Correct answer)
- To specify the security tools the provider will use to protect customer data
- To outline the customer's internal security policies for cloud use
- To define the technical architecture of the cloud deployment
Correct answer: To establish measurable performance commitments, uptime guarantees, and remedies for service failures
An SLA formalizes performance expectations such as uptime guarantees (e.g., 99.9%), response times, and the remedies or penalties applicable if the provider fails to meet commitments.
Question 92: Which cloud application security component validates the identity of API consumers using client credentials before granting access?
- Load balancer health check
- DNS resolver
- API Key / OAuth 2.0 Client Credentials flow (Correct answer)
- Content Delivery Network (CDN)
Correct answer: API Key / OAuth 2.0 Client Credentials flow
API keys or the OAuth 2.0 client credentials grant are used to authenticate machine-to-machine API consumers, ensuring only authorized clients can call the API.
Question 93: NIST SP 800-145 defines cloud computing with five essential characteristics, three service models, and how many deployment models?
- Five
- Three
- Two
- Four (Correct answer)
Correct answer: Four
NIST SP 800-145 defines four cloud deployment models: private cloud, community cloud, public cloud, and hybrid cloud.
Question 94: What is the primary focus of the EU General Data Protection Regulation (GDPR) as it applies to cloud computing?
- Protection of EU residents' personal data and enforcement of privacy rights including consent, access, and erasure (Correct answer)
- Security certification requirements for cloud providers
- Network performance standards for cloud services
- Cloud service pricing transparency
Correct answer: Protection of EU residents' personal data and enforcement of privacy rights including consent, access, and erasure
GDPR mandates how organizations collect, process, store, and delete EU residents' personal data, imposing strict consent requirements, data subject rights, and breach notification obligations.
Question 95: In cloud incident response, what does the containment phase primarily involve?
- Documenting lessons learned
- Identifying the root cause of the incident
- Limiting the spread and impact of the incident to prevent further damage (Correct answer)
- Restoring systems to normal operation
Correct answer: Limiting the spread and impact of the incident to prevent further damage
Containment stops the attack from spreading by isolating affected systems, revoking compromised credentials, and blocking malicious traffic.
Question 96: What physical hardware must be secured in order to prevent unauthorized access to systems?
- BIOS (Correct answer)
- RDP
- ALOM
- SSH
Correct answer: BIOS
The firmware that runs the actual initiation and booting of a piece of hardware is referred to as the BIOS. If it is compromised, an attacker could get access to hosted systems and change configuration settings, exposing or disabling various security features.
Question 97: In cloud forensics, why is evidence collection challenging compared to traditional on-premises forensics?
- Cloud environments have no logging capabilities
- Evidence may be distributed across multiple jurisdictions, shared infrastructure makes isolation difficult, and data may be volatile or ephemeral (Correct answer)
- Cloud providers do not allow forensic access
- Cloud forensics only applies to IaaS
Correct answer: Evidence may be distributed across multiple jurisdictions, shared infrastructure makes isolation difficult, and data may be volatile or ephemeral
Cloud forensics is complicated by data being spread across multiple countries, shared hardware making chain of custody complex, and auto-scaling that may destroy evidence by terminating instances.
Question 98: Which cloud security practice involves regularly reviewing and removing unused IAM accounts, roles, and permissions?
- Access entitlement review (access recertification) (Correct answer)
- Penetration testing
- Security awareness training
- Threat intelligence integration
Correct answer: Access entitlement review (access recertification)
Access entitlement reviews (also called access recertification or user access reviews) periodically verify that all IAM grants are still needed and remove those that are not.
Question 99: What is the primary function of a Cloud Access Security Broker (CASB)?
- To enforce security policies between cloud users and cloud service providers (Correct answer)
- To provide load balancing for cloud workloads
- To optimize application performance across cloud regions
- To manage virtual machine provisioning in the cloud
Correct answer: To enforce security policies between cloud users and cloud service providers
A CASB serves as an intermediary between cloud users and cloud providers, enforcing security policies, providing visibility into cloud usage, and ensuring regulatory compliance.
Question 100: Which security practice involves deliberately testing an application by providing random, unexpected, or malformed input?
- Fuzz testing (fuzzing) (Correct answer)
- Load testing
- Unit testing
- Penetration testing
Correct answer: Fuzz testing (fuzzing)
Fuzz testing (fuzzing) bombards an application with random or malformed inputs to discover crashes, exceptions, and security vulnerabilities the developer didn't anticipate.
Question 101: What is a key indicator of compromise (IoC) in cloud security monitoring?
- An artifact or observation (e.g., unusual API calls, impossible travel logins) that suggests a system may have been breached (Correct answer)
- A scheduled maintenance window
- A routine log rotation event
- A successful software deployment
Correct answer: An artifact or observation (e.g., unusual API calls, impossible travel logins) that suggests a system may have been breached
IoCs are forensic artifacts such as unusual traffic patterns, unexpected geographic logins, or anomalous API calls that suggest malicious activity may have occurred.
Question 102: In a microservices architecture, what is mutual TLS (mTLS) used for?
- Managing API rate limits
- Authenticating both the client and server to each other in service-to-service communication (Correct answer)
- Encrypting data stored in databases
- Load balancing traffic between services
Correct answer: Authenticating both the client and server to each other in service-to-service communication
mTLS requires both communicating parties to present certificates, ensuring that each microservice can verify the identity of the other before exchanging data.
Question 103: Which approach best secures secrets (API keys, passwords) in a cloud-native application?
- Using a dedicated secrets management service (e.g., HashiCorp Vault, AWS Secrets Manager) (Correct answer)
- Storing them in environment variables in plain text
- Hardcoding them in application source code
- Emailing them to developers as needed
Correct answer: Using a dedicated secrets management service (e.g., HashiCorp Vault, AWS Secrets Manager)
Dedicated secrets management services provide centralized, audited, and access-controlled storage for secrets, with automatic rotation capabilities.
Question 104: What type of code testing and review is the safest?
- Open source
- Combination of open source and proprietary (Correct answer)
- Proprietary/internal
- Neither the open source nor proprietary
Correct answer: Combination of open source and proprietary
The combination of open source and proprietary code testing and review can be a beneficial approach for enhancing the security of software. Open source code allows for community-driven scrutiny, which can result in the discovery and resolution of vulnerabilities by a larger pool of developers. Proprietary code, on the other hand, offers the advantage of controlled access and confidentiality, limiting exposure to potential attackers. <br> By leveraging both open source and proprietary code testing and review, organizations can benefit from the strengths of each approach. Open source provides transparency, peer review, and rapid bug detection and fixing, while proprietary code allows for more stringent control and protection of sensitive code. The combination helps identify vulnerabilities and implement appropriate security measures, making it a more robust strategy for code testing and review.
Question 105: What is the primary security concern with a hypervisor in a multi-tenant cloud environment?
- A compromised hypervisor can expose all guest VMs running on that host (Correct answer)
- Hypervisors increase network latency significantly
- Hypervisors prevent the use of firewalls
- Hypervisors cannot support encrypted VMs
Correct answer: A compromised hypervisor can expose all guest VMs running on that host
Because the hypervisor controls all VMs on a host, a vulnerability in it can allow an attacker to break out of one VM and access others on the same physical host.
Question 106: What is a key security risk of using shared storage in a multi-tenant cloud environment?
- Reduced redundancy
- Increased latency
- Higher cost
- Data remnance — residual data from one tenant being accessible to another (Correct answer)
Correct answer: Data remnance — residual data from one tenant being accessible to another
Data remnance (or data remanence) is the risk that deleted data from one tenant persists on shared storage and could potentially be read by another tenant.
Question 107: What is the purpose of an API gateway in cloud application security?
- To store API credentials securely
- To back up API response data
- To enforce authentication, rate limiting, and traffic management for API calls (Correct answer)
- To compile API source code
Correct answer: To enforce authentication, rate limiting, and traffic management for API calls
An API gateway centralizes authentication, authorization, rate limiting, and logging for all API traffic, acting as a single controlled entry point.
Question 108: Which cloud service model delivers a complete software application over the internet, managed entirely by the cloud provider with the least customer control over underlying infrastructure?
- PaaS (Platform as a Service)
- SaaS (Software as a Service) (Correct answer)
- IaaS (Infrastructure as a Service)
- FaaS (Function as a Service)
Correct answer: SaaS (Software as a Service)
SaaS delivers fully managed software applications where the provider manages infrastructure, platform, and application layers, leaving customers responsible only for user access and data.
Question 109: What does a runtime application self-protection (RASP) solution do?
- Monitors network traffic outside the application
- Instruments the application to detect and block attacks in real time from within the running process (Correct answer)
- Performs static analysis of container images
- Scans source code before compilation
Correct answer: Instruments the application to detect and block attacks in real time from within the running process
RASP integrates into the application runtime to monitor execution, detect attack patterns, and block malicious actions from within the application itself.
Question 110: Cryptographic erasure (crypto-shredding) destroys data by doing what?
- Applying degaussing to the storage medium
- Overwriting data 7 times with random bits
- Physically shredding the hard drive
- Deleting the encryption key so encrypted data becomes permanently inaccessible (Correct answer)
Correct answer: Deleting the encryption key so encrypted data becomes permanently inaccessible
Crypto-shredding deletes the encryption key, making encrypted data permanently unreadable without needing to overwrite or physically destroy the media.
Question 111: What is a major security concern with serverless (FaaS) applications in the cloud?
- Serverless platforms do not support logging
- Serverless functions cannot use HTTPS
- Functions are too slow for security-sensitive workloads
- Insecure function triggers and over-permissive IAM roles granting excessive access (Correct answer)
Correct answer: Insecure function triggers and over-permissive IAM roles granting excessive access
Serverless functions are often granted overly broad IAM permissions and may be triggered by insecure event sources, creating privilege escalation and injection risks.
Question 112: Which network security control is typically used at the boundary of a cloud VPC to filter inbound and outbound traffic?
- Intrusion Prevention System (IPS)
- Security Group / Network Access Control List (NACL) (Correct answer)
- Web Application Firewall (WAF)
- Data Loss Prevention (DLP)
Correct answer: Security Group / Network Access Control List (NACL)
Security Groups and NACLs are cloud-native controls that filter traffic at the VPC or subnet level based on IP, port, and protocol rules.
Question 113: Which of the following positions is responsible for an organization's billing, purchasing, and requesting audit reports in a cloud environment?
- Cloud service business manager (Correct answer)
- Cloud service user
- Cloud service Integrator
- Cloud service administrator
Correct answer: Cloud service business manager
The cloud service business manager is in charge of supervising business and billing administration, purchasing cloud services, and obtaining audit reports as needed.
Question 114: Which of the following statements best characterizes VLANs?
- They are not restricted to the name rack but restricted to the same data center.
- They are restricted to the same racks and data centers.
- They are not restricted to the same rack but restricted to same switches.
- They are not restricted to the same data center or the same racks. (Correct answer)
Correct answer: They are not restricted to the same data center or the same racks.
A virtual area network (VLAN) can span any network within a data center, or it can span many physical locations and data centers.
Question 115: Which risk treatment option involves transferring the financial impact of a risk to a third party?
- Risk transference (Correct answer)
- Risk mitigation
- Risk avoidance
- Risk acceptance
Correct answer: Risk transference
Risk transference shifts the financial consequences of a risk to a third party, most commonly through cyber liability insurance or contractual indemnification clauses.
Question 116: Which data security technique ensures that data remains protected even if the storage medium is stolen?
- Data masking
- Encryption at rest (Correct answer)
- Data classification
- Data tokenization
Correct answer: Encryption at rest
Encryption at rest protects data stored on physical media by rendering it unreadable without the correct decryption key.
Question 117: Which OWASP Top 10 vulnerability involves attackers manipulating SQL queries by injecting malicious input?
- Insecure Deserialization
- SQL Injection (Correct answer)
- Broken Access Control
- Security Misconfiguration
Correct answer: SQL Injection
SQL injection occurs when user-supplied input is incorporated into a SQL query without proper sanitization, allowing attackers to manipulate the database.
Question 118: What is the primary security benefit of using immutable logging in cloud environments?
- Logs are compressed for cost efficiency
- Logs cannot be altered or deleted by attackers, preserving forensic integrity (Correct answer)
- Logs are automatically analyzed for compliance
- Logs are automatically shared with law enforcement
Correct answer: Logs cannot be altered or deleted by attackers, preserving forensic integrity
Immutable logs use write-once storage or append-only mechanisms so that even a fully compromised account cannot alter historical log records, preserving evidence integrity.
Question 119: Which concept describes the minimum level of access rights a user or system should be granted to perform their required functions?
- Separation of duties
- Need to know
- Defense in depth
- Principle of least privilege (Correct answer)
Correct answer: Principle of least privilege
The principle of least privilege limits access rights to only what is necessary for the user's role, minimizing the potential damage from accidents or compromised credentials.
Question 120: Which threat modeling framework uses the mnemonic STRIDE to categorize threats?
- PASTA framework
- NIST RMF
- Microsoft STRIDE model (Correct answer)
- OWASP Threat Dragon
Correct answer: Microsoft STRIDE model
Microsoft's STRIDE model categorizes threats as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Question 121: What is OAuth 2.0 primarily used for in cloud applications?
- Multi-factor authentication
- Encrypting data in transit
- Delegated authorization, allowing applications to access resources on behalf of users without sharing credentials (Correct answer)
- Digital certificate management
Correct answer: Delegated authorization, allowing applications to access resources on behalf of users without sharing credentials
OAuth 2.0 is an authorization framework that enables a third-party application to obtain limited access to a service on behalf of a user without exposing their password.
Question 122: In cloud data security, what does IRM (Information Rights Management) primarily protect?
- Physical hardware in the data center
- Database connection strings
- Documents and files after they leave the organization (Correct answer)
- Network packets in transit
Correct answer: Documents and files after they leave the organization
IRM enforces usage policies on documents and files so that access controls follow the content even outside the organization's perimeter.
Question 123: What is the difference between an RTO and an RPO in cloud disaster recovery planning?
- RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss measured in time (Correct answer)
- RTO measures data loss; RPO measures downtime
- Both measure the same metric from different perspectives
- RTO applies to databases; RPO applies to applications
Correct answer: RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss measured in time
RTO (Recovery Time Objective) defines how long the system can be down, while RPO (Recovery Point Objective) defines how much data loss (measured in time) is acceptable.
Question 124: Which NIST cloud computing characteristic describes the ability of cloud resources to be provisioned and released rapidly to scale elastically with demand?
- Resource pooling
- Rapid elasticity (Correct answer)
- Measured service
- Broad network access
Correct answer: Rapid elasticity
Rapid elasticity allows cloud resources to be provisioned and released quickly—automatically in some cases—to scale with demand, appearing unlimited to the consumer.
Question 125: Which standard establishes requirements for information security management systems (ISMS) and is commonly pursued by cloud providers to demonstrate security governance maturity?
- SOC 2
- ISO/IEC 27001 (Correct answer)
- PCI DSS
- NIST CSF
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for ISMS that defines requirements for establishing, implementing, maintaining, and continuously improving an organization's information security program.
Certified Cloud Security Professional (CCSP)
The CCSP certification validates advanced technical skills to design, manage, and secure data, applications, and infrastructure in the cloud using best practices, policies, and procedures. It covers six domains spanning cloud concepts, data security, platform security, application security, security operations, and legal/compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds